Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2721▲ 17 respecto a la semana anterior
Críticas / altas1459▲ 351 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)72▼ 458 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.1% | — | Phpmywind | 20/6/2023 | 17/6/2026 | SQL injection vulnerability in gaozhifeng PHPMyWind v.5.6 allows a remote attacker to execute arbitrary code via the id variable in the modify function. | |
| Modificada | Alta (8.8) | 0.92% | — | Phpmywind | 4/4/2023 | 17/6/2026 | SQL injection vulnerability found in PHPMyWind v.5.6 allows a remote attacker to gain privileges via the delete function of the administrator management page. | |
| Modificada | Media (6.5) | 0.52% | — | Phpmywind | 14/10/2021 | 9/7/2026 | A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator account without authentication. | |
| Modificada | Alta (7.2) | 2.8% | — | Phpmywind | 7/9/2021 | 17/6/2026 | PHPMyWind 5.6 is vulnerable to Remote Code Execution. Becase input is filtered without "<, >, ?, =, `,...." In WriteConfig() function, an attacker can inject php code to /include/config.cache.php file. | |
| Modificada | Alta (7.2) | 1.8% | — | Phpmywind | 20/8/2021 | 17/6/2026 | Unrestricted File Upload in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the component 'admin/upload_file_do.php'. | |
| Modificada | Alta (7.2) | 3.6% | — | Phpmywind | 20/8/2021 | 17/6/2026 | Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the component '/admin/web_config.php'. | |
| Modificada | Media (4.8) | 0.98% | — | Phpmywind | 27/5/2021 | 17/6/2026 | Cross Site Scripting (XSS) in PHPMyWind v5.5 allows remote attackers to execute arbitrary code by injecting scripts into the parameter "$cfg_switchshow" of component " /admin/web_config.php". | |
| Modificada | Media (4.8) | 0.93% | — | Phpmywind | 27/5/2021 | 17/6/2026 | Cross Site Scripting (XSS) in PHPMyWind v5.5 allows remote attackers to execute arbitrary code by injecting scripts into the parameter "$cfg_copyright" of component " /admin/web_config.php". | |
| Modificada | Media (4.8) | 0.65% | — | Phpmywind | 23/9/2019 | 17/6/2026 | admin/infoclass_update.php in PHPMyWind 5.6 has stored XSS. | |
| Modificada | Media (6.1) | 0.83% | — | Phpmywind | 23/9/2019 | 17/6/2026 | admin/infolist_add.php in PHPMyWind 5.6 has stored XSS. | |
| Modificada | Media (6.1) | 0.87% | — | Phpmywind | 7/3/2019 | 17/6/2026 | An issue was discovered in PHPMyWind 5.5. The method parameter of the data/api/oauth/connect.php page has a reflected Cross-site Scripting (XSS) vulnerability. | |
| Modificada | Media (6.1) | 0.87% | — | Phpmywind | 7/3/2019 | 17/6/2026 | An issue was discovered in PHPMyWind 5.5. The username parameter of the /install/index.php page has a stored Cross-site Scripting (XSS) vulnerability, as demonstrated by admin/login.php. | |
| Modificada | Media (4.8) | 0.59% | — | Phpmywind | 18/2/2019 | 17/6/2026 | admin/default.php in PHPMyWind v5.5 has XSS via an HTTP Host header. | |
| Modificada | Media (4.9) | 1.7% | — | Phpmywind | 5/2/2019 | 17/6/2026 | An issue was discovered in PHPMyWind 5.5. It allows remote attackers to delete arbitrary folders via an admin/database_backup.php?action=import&dopost=deldir&tbname=../ URI. | |
| Modificada | Media (6.1) | 0.44% | — | Phpmywind | 5/2/2019 | 17/6/2026 | An issue was discovered in PHPMyWind 5.5. The GetQQ function in include/func.class.php allows XSS via the cfg_qqcode parameter. This can be exploited via CSRF. | |
| Modificada | Alta (7.2) | 2.1% | — | Phpmywind | 17/9/2018 | 17/6/2026 | admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjunction with a crafted cfg_webpath field. | |
| Modificada | Alta (7.2) | 2.1% | — | Phpmywind | 17/9/2018 | 17/6/2026 | admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the rewrite url setting. | |
| Modificada | Alta (7.2) | 2.1% | — | Phpmywind | 17/9/2018 | 17/6/2026 | admin/goods_update.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the attrvalue[] array parameter. | |
| Modificada | Alta (7.2) | 2.1% | — | Phpmywind | 17/9/2018 | 17/6/2026 | admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the varvalue field. | |
| Modificada | Media (5.4) | 0.64% | — | Phpmywind | 17/9/2018 | 17/6/2026 | PHPMyWind 5.5 has XSS in member.php via an HTTP Referer header, | |
| Modificada | Media (6.1) | 0.79% | — | Phpmywind | 26/5/2018 | 17/6/2026 | PHPMyWind 5.5 has XSS via the cid parameter to newsshow.php, or the query string to news.php or about.php. | |
| Modificada | Media (6.1) | 2.2% | — | Phpmywind | 21/8/2017 | 17/6/2026 | PHPMyWind 5.3 has XSS in shoppingcart.php, related to message.php, admin/message.php, and admin/message_update.php. |